Trust and security
You’re in charge. And you can check it.
Giving an AI access to your email and your data is a serious decision. Here is how AIRON works inside, with what is already in place and what isn’t yet.
The journey of an email
What happens, and where, from the moment an email arrives until the reply goes out.
-
01
It reaches your inbox
Gmail, Outlook or any IMAP mailbox. Your mailbox is still yours.
Your email provider
-
02
It is stored and indexed
The content AIRON needs is stored on our servers and indexed so it can be searched.
Frankfurt (EU) · IONOS and Google Cloud
-
03
The AI drafts a proposal
The language model prepares the draft with your company’s context and tone.
United States · OpenAI
-
04
A person decides
The draft waits in Approvals. You edit it, approve it or reject it with a reason.
Your team
-
05
It goes out and is recorded
It is sent once, from your mailbox and with your signature, and recorded in Activity.
Your mailbox · Activity
Who decides what goes out
Two different rules depending on who starts the action.
What AIRON starts on its own
Replies to incoming emails, flow steps that send something out and posts proposed by AIRON. They always wait for a person: they can be blocked, but never left on automatic.
What you ask for
In the chat or on WhatsApp, anything that goes to third parties, is tax-related or spends money asks for approval by default. Internal things happen right away and, for events and AIRON CRM, can be undone. The account administrator can adjust each tool; the Alegra invoice always asks for approval.
| Action | By default |
|---|---|
| Send an email | Asks for approval |
| Issue an invoice (Facturales) | Asks for approval |
| Pause or change an Ads campaign | Asks for approval |
| Post on Instagram | Asks for approval |
| Create an event with guests | Asks for approval |
| Changes in GitHub, Vercel, Supabase or Dropbox | Asks for approval |
| Create a task or note in AIRON CRM | Happens right away |
| Create an event without guests | Happens right away |
| Read, search and summarise | Happens right away |
Approving is a permission
Only people with the approval permission can send, whether from the inbox, the chat or by replying “yes” on WhatsApp. And each draft is sent only once, on the version you saw.
Who sees what
| Your chat | Company approvals | Connectors and permissions | |
|---|---|---|---|
| You | Yes | Yes | Depends on role |
| Your colleagues | No | Yes | Depends on role |
| Your Superadmin | No | Yes | Yes |
| Other companies | No | No | No |
There are two roles: Superadmin, who manages the team and permissions, and Member. Your chat is private: AIRON never quotes what you wrote to anyone. With Microsoft 365, your drafts go out from your own mailbox and only you see them.
Your company, isolated from the rest
Each company has its own space and every query —including document searches and memory— is filtered by that space before returning anything. If the filter cannot be applied, the query fails instead of returning too much.
Your data, yours
-
Download it whenever you want
All your data as a ZIP from Management.
-
If you leave, it’s deleted
Conversations, memory, files and credentials. Only what the law requires is kept; backups roll over within 30 days.
-
Encrypted credentials
Your connector credentials are stored encrypted and tied to your company; you can revoke them whenever you want.
EU AI Act
-
You always know it’s AI
A notice in the chat, a footer in emails and on WhatsApp, and a verifiable signature on the PDFs and images it generates.
-
Limited risk, monitored
An automatic control prevents adding a high-risk purpose without first opening the conformity file.
-
AI training
AIRON Academy records each person’s training, which is what Article 4 of the Act asks for.
Operational security
- Encrypted connections (TLS 1.2 and 1.3) with HSTS
- Server logs without tokens or secrets
- Encrypted off-server backups, with tested restores
- Blocking of repeated login attempts
- Vulnerability disclosure channel (security.txt)
- Data processing agreement accepted and versioned from the first login
What we don’t have yet
- ISO 27001, SOC 2 or ENS certifications
- External penetration test
- Language model processed in the EU
- Signed processing agreements with every provider (in progress)
- Automatic anonymisation of personal data before the AI (in development, not yet active)
If you need any of this to decide, write to security@airon.team and we’ll tell you where it stands.